SSE-ENGINEER Exam Questions
60 real SSE-ENGINEER exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Remote Network Configuration
A large retailer has deployed all of its stores with the same IP address subnet. An engineer is onboarding these stores as Remote Networks in Prisma Access. While onboarding each s...
overlapping subnetsRemote NetworksPrisma Accesstraffic flow - Question #2Security Policy Configuration
An intern is tasked with changing the Anti-Spyware Profile used for security rules defined in the GlobalProtect folder. All security rules are using the Default Prisma Profile. The...
Anti-Spyware Profiledefault profilesprofile groupsGlobalProtect folder - Question #3Identity and Access Management
How can role-based access control (RBAC) for Prisma Access (Managed by Strata Cloud Manager) be used to grant each member of a security team full administrative access to manage th...
RBACmultitenant deploymentStrata Cloud ManagerPrisma Access - Question #4Security Policy Configuration
An engineer configures a Security policy for traffic originating at branch locations in the Remote Networks configuration scope. After committing the configuration and reviewing th...
Security policyconfiguration scopeRemote Networkstraffic matching - Question #5Operations and Maintenance
What is the flow impact of updating the Cloud Services plugin on existing traffic flows in Prisma Access?
Cloud Services pluginupgradetraffic flowsPrisma Access - Question #6Remote Network Connectivity
Which overlay protocol must a customer premises equipment (CPE) device support when terminating a Partner Interconnect-based Colo-Connect in Prisma Access?
Partner InterconnectColo-ConnectIPSecCPE - Question #7Endpoint and Browser Security
Which policy configuration in Prisma Access Browser (PAB) will protect an organization from malicious BYOD and minimize the impact on the user experience?
Prisma Access BrowserBYODdata maskingwatermarking - Question #8Authentication and Identity
During a deployment of Prisma Access (Managed by Strata Cloud Manager) for mobile users, a SAML authentication type and authentication profile in the Cloud Identity Engine applicat...
SAMLCloud Identity Engineauthentication profilemobile users - Question #9GlobalProtect Configuration
After configuring domain-based split tunnel for zoom.us, how is expected behavior on the client machine confirmed?
split tunnelGlobalProtectrouting tableDNS - Question #10Identity and Access Management
Which Cloud Identity Engine capability will create a Security policy that uses Entra ID attributes as the source identification?
Cloud Identity EngineEntra IDdynamic user groupsSecurity policy - Question #11Troubleshooting and Diagnostics
An engineer deploys a new branch connected to Prisma Access. From the customer premises equipment (CPE) device at the branch, Phase 1 on the tunnel is established, but Phase 2- enc...
IPSec Phase 2tunnel logsStrata Logging ServiceRemote Networks - Question #12Security Services Configuration
When configuring Remote Browser Isolation (RBI) with Prisma Access (Managed by Strata Cloud Manager), which element is required to define the protected URLs for mobile users?
Remote Browser IsolationURL access managementSecurity policymobile users - Question #13Threat Prevention
A malicious user is attempting to connect to a blocked website by crafting a packet using a fake SNI and the correct website in the HTTP host header. Which option will prevent this...
SNI mismatchSSL decryptiondomain frontingHTTP host header - Question #14Mobile User Security
A user connected to Prisma Access reports that traffic intermittently is denied after matching a Catch-All Deny rule at the bottom and bypassing HIP-based policies. Refreshing VPN...
HIPuser mappingGlobalProtectVPN session - Question #15SaaS Security
Which feature can help address a customer concern about the length of time it takes to update their SaaS-allowed IP addresses while onboarding to Prisma Access?
SaaSIP addressestraffic steeringonboarding - Question #16Monitoring and Analytics
Which feature within Strata Cloud Manager (SCM) allows an operations team to view applications, threats, and user insights for branch locations for both NGFW and Prisma Access simu...
Command CenterStrata Cloud ManagerNGFWPrisma Access monitoring - Question #17Data Security
In addition to creating a Security policy, how can an AI Access Security be used to prevent users from uploading financial information to ChatGPT?
AI Access SecurityEnterprise DLPChatGPTdata loss prevention - Question #18Authentication and PKI
Which statement is valid in relation to certificates used for GlobalProtect and pre-logon?
GlobalProtectpre-logoncertificatesMachine Certificate Store - Question #19Zero Trust Network Access
What must be configured to accurately report an application's availability when onboarding a discovered application for ZTNA Connector?
ZTNA Connectorapplication discoveryhealth checktcp ping - Question #20Troubleshooting and Diagnostics
All mobile users are unable to authenticate to Prisma Access (Managed by Strata Cloud Manager) using SAML authentication through the Cloud Identity Engine. Users report that after...
SAMLCloud Identity Enginemetadata configurationauthentication failure - Question #21Remote Network Connectivity and Troubleshooting
An engineer has configured a new Remote Networks connection using BGP for route advertisements. The IPSec tunnel has been established, but the BGP peer is not up. Which two element...
BGP peeringRemote NetworksIPSec tunnelroute advertisement - Question #22Mobile User Connectivity
In an Explicit Proxy deployment where no agent can be used on the endpoint, which authentication method is supported with mobile users?
Explicit ProxySAML authenticationagentless deploymentmobile users - Question #23Prisma Access Administration and Operations
Which advanced AI-powered functionality does Strata Copilot provide to enhance the capabilities of Prisma Access security teams?
Strata CopilotAI-powered assistanceissue resolutionPrisma Access - Question #24AI Access Security
Where are tags applied to control access to Generative AI when implementing AI Access Security?
AI Access SecurityGenerative AI classificationapplication taggingsanctioned apps - Question #25SaaS Security
How can an engineer use risk score customization in SaaS Security Inline to limit the use of unsanctioned SaaS applications by employees within a Security policy?
SaaS Security Inlinerisk score customizationapplication filterunsanctioned SaaS - Question #26Troubleshooting Prisma Access
Which two Prisma Access tools help troubleshoot connectivity issues for mobile users? (Select two)
mobile user troubleshootingreal-time monitoringActivity Insightsconnectivity tools - Question #27Troubleshooting Prisma Access
An administrator notices that Prisma Access users experience intermittent connection drops. What should be the first step in troubleshooting?
connection dropstroubleshooting methodologyreal-time monitoringmobile users - Question #28Security Monitoring and Visibility
How does Prisma Access Traffic Replication support security monitoring?
traffic replicationtraffic mirroringsecurity monitoringexternal tools - Question #29Security Policy Management
Prisma Access enables organizations to manage user-based security policies using __________.
User-IDuser-based policiesidentity enforcementPrisma Access - Question #30Prisma Access Deployment Design
A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers....
deployment architecturemulti-tenant designmobile usersB2B connectivity - Question #31Prisma Access Deployment Design
A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to- business (B2B) partners to their data centers...
GlobalProtectRemote Networksinternet filteringdeployment design - Question #32Remote Network Connectivity and Troubleshooting
A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to- business (B2B) partners to their data centers...
eBGP routingRemote Networksstatic routesbranch connectivity - Question #33Service Connectivity
A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to- business (B2B) partners to their data centers...
service connectionsColo-Connectdata center accessB2B connectivity - Question #34Prisma Access Administration and Operations
Which two actions can a company with Prisma Access deployed take to use the Egress IP API to automate policy rule updates when the IP addresses used by Prisma Access change? (Choos...
Egress IP APIwebhook automationclient certificateIP address management - Question #35Prisma Access Administration and Operations
How can an engineer verify that only the intended changes will be applied when modifying Prisma Access policy configuration in Strata Cloud Manager (SCM)?
Strata Cloud Managerconfiguration previewpush dialoguechange management - Question #36Security Monitoring and Visibility
When using the traffic replication feature in Prisma Access, where is the mirrored traffic directed for analysis?
traffic replicationtraffic mirroringsecurity appliancemonitoring destination - Question #37IoT Security
When a review of devices discovered by IoT Security reveals network routers appearing multiple times with different IP addresses, which configuration will address the issue by show...
IoT Securitydevice deduplicationdevice managementmulti-interface devices - Question #38Security Policy Management
What is the impact of selecting the "Disable Server Response Inspection" checkbox after confirming that a Security policy rule has a threat protection profile configured?
server response inspectionthreat protection profilesecurity policytraffic inspection bypass - Question #39Remote Network Connectivity and Troubleshooting
A company has a Prisma Access deployment for mobile users in North America and Europe. Service connections are deployed to the data centers on these continents, and the data center...
BGP routingservice connectionsregional routingmobile user prefix filtering - Question #40SSL/TLS Decryption
Based on the image below, which two statements describe the reason and action required to resolve the errors? (Choose two.)
SSL/TLS decryptioncertificate pinningdo-not-decrypt ruledecryption error analysis - Question #41Monitoring and Troubleshooting Prisma Access
Which monitoring tool in Prisma Access allows administrators to analyze and troubleshoot real- time user traffic?
Activity Insightstraffic monitoringreal-time analysisPrisma Access - Question #42Configure Identity and Access Management in Prisma Access
What are two methods used to configure identity authentication in Prisma Access? (Select two)
identity authenticationSAMLLDAPuser authentication - Question #43Prisma Access Network Architecture and Design
In Prisma Access, how does backbone routing benefit network performance?
backbone routingnetwork performancelow-latency routingPrisma Access locations - Question #44Administer and Manage Prisma Access Multi-Tenancy
How can a network security team be granted full administrative access to a tenant's configuration while restricting access to other tenants by using role-based access control (RBAC...
RBACmultitenantAccess DomainPanorama Managed Prisma Access - Question #45Configure and Troubleshoot Security Policies in Prisma Access
An engineer has configured a Web Security rule that restricts access to certain web applications for a specific user group. During testing, the rule does not take effect as expecte...
rule hierarchyWeb Security policypolicy troubleshootingGlobalProtect - Question #46Deploy and Configure ZTNA Connectors
What will cause a connector to fail to establish a connection with the cloud gateway during the deployment of a new ZTNA Connector in a data center?
ZTNA Connectordouble NATcloud gatewayconnector deployment - Question #47Configure Identity and Access Management in Prisma Access
Which feature will fetch user and group information to verify whether a group from the Cloud Identity Engine is present on a security processing node (SPN)?
Cloud Identity Engineuser-group mappingSASE Health Dashboardsecurity processing node - Question #48Configure and Troubleshoot User-ID in Prisma Access
An engineer configures User-ID redistribution from an on-premises firewall connected to Prisma Access (Managed by Panorama) using a service connection. After committing the configu...
User-ID redistributionPanorama templatesservice connectionpre-shared keys - Question #49Configure Security Policies in Prisma Access
What is the purpose of embargo rules in Prisma Access?
embargo rulesgeo-blockingcountry restrictionssecurity policy - Question #50Configure and Manage Logging in Prisma Access
Strata Logging Service is configured to forward logs to an external syslog server; however, a month later, there is a disruption on the syslog server. Which action will send the mi...
Strata Logging Servicelog replaysyslog forwardinglog recovery